Back

Privacy Policy

Last updated: 24 February 2026

1. Who we are

BrikkPM is a property management tool that helps UK landlords track properties, tenants, finances, compliance deadlines, and maintenance. BrikkPM is operated by FRK Holdings LTD (company no. 15615224), a company registered in England and Wales. This privacy policy explains how we collect, use, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What data we collect

We collect and process the following personal data:

  • Account data: your name, email address, and profile picture (provided by Google or Microsoft when you sign in)
  • Property data: addresses, property types, purchase prices, mortgage details, and other property information you enter
  • Tenant data: tenant names, contact details, tenancy dates, and rent amounts you enter
  • Financial data: rent payments, expenses, and letting agent fee details you enter
  • Compliance data: certificate types, expiry dates, and document references you enter
  • Maintenance data: maintenance requests and contractor details you enter
  • HMRC identifiers: your Unique Taxpayer Reference (UTR) and National Insurance number (NINO), if you choose to enter them. These are encrypted using AES-256-GCM before storage.

We do not collect any data automatically beyond what is required for authentication. We do not use analytics, tracking cookies, or third-party advertising.

3. How we use your data

We use your data solely to:

  • Authenticate you and maintain your session
  • Display and manage your property portfolio
  • Calculate financial summaries and compliance deadlines
  • Generate CSV exports when you request them

We do not sell, share, or transfer your data to any third parties for marketing or other purposes.

4. Lawful basis for processing

We process your data under the following lawful bases:

  • Contract: processing is necessary to provide you with the service you signed up for
  • Legitimate interest: helping you manage your property business effectively
5. Where your data is stored

Your data is stored in a PostgreSQL database hosted by Railway (railway.app). Railway's infrastructure is hosted on Google Cloud Platform. Data may be processed in the EU or US. We rely on appropriate safeguards for any international transfers.

6. How long we keep your data

We retain your data for as long as your account is active. If you delete your account, all associated data (properties, tenants, financial records, compliance items, and documents) will be permanently removed within 30 days.

7. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct any inaccurate data (you can do this directly in the app)
  • Erasure — request deletion of your account and all associated data
  • Portability — receive your data in a machine-readable format (CSV export)
  • Objection — object to processing based on legitimate interest

To exercise any of these rights, email us at getbrikkpm@gmail.com or use our contact form. We will respond within 30 days.

8. Third-party services
  • Google OAuth: used for authentication only. We receive your name, email, and profile picture. See Google's Privacy Policy.
  • Microsoft Azure AD: used for authentication only (if you sign in with Microsoft). We receive your name, email, and profile picture. See Microsoft's Privacy Statement.
  • Railway: database and application hosting. See Railway's Privacy Policy.
  • Stripe: payment processing for paid subscriptions. We share your email address with Stripe to create a customer record. Stripe handles all card details directly — we never see or store your card number. See Stripe's Privacy Policy.
9. Changes to this policy

We may update this policy from time to time. Any changes will be posted on this page with an updated date. Continued use of the service after changes constitutes acceptance of the revised policy.

10. Contact

If you have any questions about this privacy policy or how we handle your data, email us at getbrikkpm@gmail.com or use our contact form.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.